Alexandro.Net

Download README · GitHub release

@stackline/deep-is

Stack-safe deep equality with the proven deep-is 0.1.4 semantics.

npm version license GitHub repository Docs Reddit community

Documentation | npm | Issues | Repository

Current package version: 1.0.4


Why this package?

Stack-safe deep equality with the established deep-is@0.1.4 behavior.

This package is an independent, maintained continuation of deep-is. It keeps the callable API and its intentionally loose compatibility semantics while handling cyclic and very deep object graphs without recursive call-stack exhaustion.

Provenance

The upstream source and authorship history are documented in UPSTREAM_AUDIT.md and NOTICE. The Stackline fork is not affiliated with or endorsed by the original authors.

Compatibility

Item Value
Package @stackline/deep-is@1.0.4
Node.js runtime >=12
CommonJS / primary entry ./index.js
ES module entry ./index.mjs
Type declarations ./index.d.ts

See COMPATIBILITY_CONTRACT.md and MIGRATION.md for the exact boundary and alias migration.

Installation

Install

npm install @stackline/deep-is

Preserve an existing require('deep-is') without changing application code:

npm install deep-is@npm:@stackline/deep-is

Usage

CommonJS

const deepIs = require('@stackline/deep-is');

deepIs({ answer: 42 }, { answer: '42' }); // true
deepIs(+0, -0); // false
deepIs(NaN, NaN); // true

ESM

import deepIs from '@stackline/deep-is';

const left = { id: 1 };
const right = { id: '1' };
left.self = left;
right.self = right;

deepIs(left, right); // true

Features and Integrations

Reliability

The original recursive algorithm can throw RangeError for equivalent cycles or sufficiently deep inputs. This implementation uses iterative graph traversal and pair tracking. Regression coverage includes a 100,000-level object graph, cyclic graphs, and more than 5,000 differential comparisons against a frozen copy of deep-is@0.1.4.

There is no published CVE or GHSA claim associated with this change.

Security

Report vulnerabilities privately as described in SECURITY.md. Do not disclose an unpatched vulnerability in a public issue.

API Surface

API

deepIs(actual, expected)

Returns a boolean. Inputs are not mutated.

The package deliberately preserves the legacy contract:

Use node:util.isDeepStrictEqual or another strict comparator when new code needs strict modern semantics.

Local Development

git clone https://github.com/alexandroit/stackline-deep-is.git
cd stackline-deep-is
npm ci
npm run verify

Release tooling uses Node.js 24.20.0 and npm 11.19.0. The consumer runtime contract remains the one documented above.

Consumer Smoke Test

Run the repository's existing consumer/package check after installing development dependencies:

npm run test:smoke

Release Checklist

Run npm run verify and inspect the package contents before release. Publish a new version through the GitHub Actions publishing workflow, using the SHA-512 digest of the reviewed tarball. Verify the exact published version, tarball integrity, and npm provenance after the run.

License

MIT. Original copyright and permission notices are preserved in LICENSE.

Credits and original authors

Original copyright, license notices and contributor acknowledgements remain part of this distribution. Stackline maintenance does not replace authorship of the original work.

Community and Links

Use this repository's issue tracker for reproducible bugs and feature requests. Join r/Stackline for examples, usage questions and release discussions.